Source |
CSO |
Identifiant |
5968883 |
Date de publication |
2022-07-27 05:00:00 (vue: 2022-07-27 13:05:32) |
Titre |
GitGuardian launches ggcanary project to help detect open-source software risks |
Texte |
Code security platform provider GitGuardian has announced the launch of a new open-source canary tokens project to help organizations detect compromised developer and DevOps environments. According to the firm, security teams can use GitGuardian Canary Tokens (ggcanary) to create and deploy canary tokens in the form of Amazon Web Services (AWS) secrets to trigger alerts as soon as they are tampered with by attackers. The release is reflective of a wider industry trend of emerging standards and initiatives designed to tackle risks surrounding the software supply chain and DevOps tools.ggcanary features “highly sensitive” intrusion detection
In a press release, GitGuardian stated organizations' continued adoption of the cloud and modern software development practices is leading to them unknowingly expanding their attack surfaces. Poorly secured internet-facing assets and corporate networks are triggering attackers to turn to components in the software supply chain like continuous integration and continuous deployment (CI/CD) pipelines as entry points, it added.To read this article in full, please click here |
Envoyé |
Oui |
Condensat |
according added adoption alerts amazon announced are article assets attack attackers aws can canary chain ci/cd click cloud code components compromised continued continuous corporate create deploy deployment designed detect detection developer development devops emerging entry environments expanding facing features firm form full ggcanary gitguardian has help here industry initiatives integration internet intrusion launch launches leading like modern networks new open organizations pipelines platform please points poorly practices press project provider read reflective release risks secrets secured security sensitive” services software soon source standards stated supply surfaces surrounding tackle tampered teams them tokens tools trend trigger triggering turn unknowingly use web wider “highly |
Tags |
Guideline
|
Stories |
|
Notes |
|
Move |
|